The Phone Was Still Ringing. WeChat Had Already Lost the Account.
The victim did not answer the call. They did not tap a link, install an application or approve a prompt. In a laboratory demonstration called WeWorm, the incoming WeChat call itself was enough to compromise the account.
Calif Security disclosed the research on 8 September after coordinating fixes with Tencent. The company says it found memory corruption in WeChat’s voice-over-IP stack, built a remote-code-execution exploit and then turned it into a worm that could move through the victim’s contact list.
Tencent told the South China Morning Post that the vulnerability had been fixed and that it had found no evidence of exploitation. Calif also says it observed no malicious campaign. This is consequential research into a powerful attack primitive, not a report that WeChat accounts are currently being taken over at scale.
The trust requirement made the worm more believable
The attacker had to be accepted as a WeChat friend before placing the malicious call. That prerequisite limits the path, but it does not make it academic. A compromised account already has a contact list full of trusted relationships.
Once the laboratory worm took control of one account, it could call that account’s friends from an identity they recognised. Each compromise supplied the trust needed for the next attempt. The social graph became part of the exploit chain.
This is the difference between a zero-click bug and a wormable zero-click bug. The first removes user interaction. The second also contains a practical mechanism for finding and reaching the next victim.
Account takeover is not the same as full phone compromise
Calif’s demonstrated result was remote code execution inside WeChat and control of the WeChat account. That can expose messages, contacts and account capabilities available to the application. It does not automatically prove unrestricted control of iOS, Android or every file on the device.
A full-device takeover would require an additional escape from the application sandbox or another route into more privileged operating-system services. The researchers explicitly distinguish that possible chain from the capability they demonstrated.
That boundary matters because zero-click research is easy to overstate. The accurate finding is still serious: an unanswered call could cross the application’s trust boundary, execute code and take control of a high-reach communications account.
AI compressed the exploit-development timeline
Calif says its AI system found the vulnerability and produced the first remote-code-execution exploit in roughly two days. Researchers then needed about another week to turn the exploit into the worm demonstration.
That is not evidence that an autonomous system independently launched a real campaign. Humans selected the target, managed the research and coordinated disclosure. The result is still strategically important because it suggests that modern models can reduce the specialised time needed to move from a memory-safety defect to a working exploit.
The defensive implication is uncomfortable. Coordinated disclosure, patch deployment and user adoption still operate on human timelines. Exploit construction may be accelerating.
Tencent fixed more than the applications
Calif reported the issue to Tencent on 24 July. WeChat 8.0.77 for Android and 8.0.76 for iOS were released on 21 August. The researchers say Tencent also deployed a server-side mitigation, which they confirmed on 28 August. Tencent confirmed the remote-code-execution finding on 4 September.
The server-side response is important for a communications platform. Mobile updates do not arrive on every device at once, and some users defer them. A service-side control can reduce exposure while the corrected clients spread through the installed base.
What users and defenders should do
- Update WeChat to at least version 8.0.77 on Android or 8.0.76 on iOS, and continue to the latest available release.
- Do not assume an unanswered call is harmless when investigating unusual account activity. Include call metadata and application events in the timeline.
- Review unexpected friend additions, outbound calls, messages and account changes that the user cannot explain.
- Protect recovery channels and linked devices. An account takeover can outlive the original application process if the attacker changes persistent settings.
- For high-risk users, reduce unnecessary contact exposure and treat unexpected friend requests as a security decision.
- Avoid claiming device-wide compromise without evidence of a second sandbox or operating-system exploit.
The BlackTree view
WeWorm combines three forms of leverage: a zero-click entry point, a communications platform with enormous reach and a contact graph that supplies trusted next targets. None of those elements is new on its own. Their combination changes the scale of the possible failure.
The good news is that the researchers disclosed the chain and Tencent responded before a known campaign emerged. The strategic warning remains. When one incoming call can become code execution, and one compromised account can locate the next trusted relationship, the time between vulnerability discovery and platform-wide risk becomes very short.
Sources
- Calif Security: WeWorm, published 8 September 2026. The page provides no exact publication time.
- South China Morning Post: US firm used AI to hijack WeChat account, published 9 September 2026 at 16:01 as displayed by the publisher.
- The Hacker News: WeChat Zero-Click Worm Took Over Accounts via Incoming Calls, published 8 September 2026. The page provides no exact publication time.


